According to Verizon's 2025 report on data breaches, nearly 60% of breaches recorded worldwide had some human element behind them — a click, a password typed into the wrong page, a phone call that convinced someone to act too fast. That is not a character flaw. It is the expected result of putting thousands of daily decisions in the hands of busy people under pressure to respond quickly.

Training helps, and helps a lot. A global 2026 study built on fake-email simulation data, from security training company KnowBe4, measured an average click rate of 33.2% in companies with no preparation at all, dropping to 4.2% after a year of continuous training. That is a real drop. It is also proof the number never reaches zero: in a hundred-person company, even after a year of training, someone is still, statistically, ready to click.

The question that decides how big the damage gets is not "how do we stop the click" — nobody stops 100% of it. It is "what does the company do in the minutes that follow." And that is exactly where most companies have no answer ready.

Why someone will always click

In a company that has already trained the whole team, sent internal warnings, and pushes people to be careful with email, this situation still happens: someone clicks, types a password into a fake page, and nobody notices right away. The warning only shows up days later, when strange emails start going out from that person's account — billing a supplier, requesting an urgent transfer, or just spreading spam to her contacts.

Across Europe, the Middle East and Africa, the fake email that poses as someone trustworthy showed up in 19% of the data breaches Verizon recorded in 2025 — behind only direct credential theft and the use of vulnerable systems. The pattern repeats: someone trusts how the message looks, because it was designed exactly for that.

The same Verizon research points to something uncomfortable: a small slice of the team concentrates most of the risk. Around 8% of employees account for 80% of incidents tied to human behavior. That does not mean the answer is watching those people more closely — it means a structure built only around "everyone be careful" leaves exactly that group without any extra safety net.

The damage is not only the information that leaked. It is the hours the team spends figuring out what happened, the supplier who calls back suspicious because they received a strange payment request from the company's own email, and the employee who spends weeks typing carefully, afraid of making the same mistake again.

When the compromised account belongs to someone in finance or customer service, the damage grows in a specific way: whoever receives the strange email is exactly the person who trusts that sender — a customer, a supplier, a colleague from another department. The message goes out from inside the company, looking right, in the middle of a conversation that already existed. That is why "finding out three days later" costs far more than "finding out right away": in three days, that account has had time to write to everyone who trusts it.

Training helps, but it does not close the door

Training helps, but it does not close the door

The common way to handle this is to train the team, send a warning, and hope for the best. It works up to a point: the numbers above show training cuts the click rate a lot. The problem is treating "cutting it" as if it were "zeroing it out" — and planning the company's security as if the click would never happen.

Another version of the same common approach is buying one more security tool and letting it run on its own, with nobody watching what it flags. An alert nobody looks at is worth the same as no alert at all — it just costs more.

The most common side effect shows up when the click happens anyway: the natural reaction is to look for who made the mistake. That teaches the wrong lesson. The next person who realizes they clicked will hesitate to say anything, afraid of getting in trouble — and every hour of delay is one more hour the compromised account stays active, reading messages, sending email, opening files.

Blaming whoever clicked is not a control. It is the absence of one. A real control does not promise to stop the click — it stops the click from turning into serious damage.

What has to be in place

An environment ready for this moment rests on verifiable mechanisms, not an internal memo.

A second confirmation step beyond the password. Even if someone types the right password into the wrong page, that second step — a code, a phone notification — does not go to whoever stole the password. The account stays locked even with the password in the wrong hands.

A short path to report it, with no fear of punishment. The person who clicked is the first to know something is wrong. If reporting is fast and does not turn into a formal warning, the alert arrives in minutes — not three days later, once the strange emails have already started going out.

An alert for out-of-pattern access reaching someone right away. A login from an unusual place or time, or a string of failed password attempts, needs to trigger a signal for whoever handles security — not just sit logged in a report nobody opens.

Immediate suspension of the suspect account. As soon as the alert comes in or the report is made, the account gets locked before it turns into a days-long investigation. Blocking the account's use right now does more than resetting the password afterward.

A map of what that account could reach. Knowing which mailboxes, folders, systems, and contacts that login had access to is what lets someone check exactly what needs attention — instead of reconstructing everything from memory under pressure.

This is how Skills IT works: with a second confirmation step beyond the password, a direct channel to report without punishment, and cutting off the suspect account's access before it turns into a bigger investigation.

What changes when the response is fast

What changes when the response is fast

The payoff is not abstract. A company that identifies and contains an incident quickly avoids most of the cascading damage: panicked password resets, a suspicious customer calling in, a supplier asking for phone confirmation before processing a payment.

The scale of the problem with acting slowly shows up in the industry numbers: in 2025, the average time companies took to identify and contain a data breach, according to IBM's report on the cost of breaches, was 241 days — the lowest in nine years, and still, months. Every extra day is a day the compromised account can keep being used.

In a small or medium-sized company, without anyone watching access all the time, that gap tends to be discovered by accident — a customer calling to ask a question, an employee noticing an email they never wrote. Cutting that gap from months to minutes does not depend on luck: it depends on having, from before the click ever happens, the second confirmation step, the alert, and the way to report it.

The financial payoff is in that: fewer hours of the team putting out fires, less risk of a wrongful payment made to a scammed supplier, and a team that keeps trusting the reporting channel instead of hiding the mistake.

There is also a less visible payoff: the right decision at the right time. When the alert arrives in minutes and the access map already exists, whoever is deciding knows exactly what to check — no need to shut down entire systems out of caution, or wait days for a full diagnosis before acting. That is time the team spends working, instead of time spent reconstructing what happened.

Four questions to bring to the next meeting

Before reviewing the training program again, it is worth asking what exists for the moment training is not enough:

  1. Is there a second confirmation step beyond the password on every important access point? If the answer is "only on some systems," the easiest account to break into today is probably the one left out.
  2. Who gets an alert when a login falls outside the normal pattern? If the answer is "no one, but it gets logged," the alert only exists on paper.
  3. Does anyone know, without rebuilding it from scratch, what a specific account can reach? Without that map, every incident turns into a long investigation even when it is a small one.
  4. If someone on the team clicked today, how long would it take the company to find out? If the answer is not minutes, it is worth understanding why before it happens for real.